CVE-2023-22054

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Jul 18, 2023
Updated: Nov 15, 2023

Summary

CVE-2023-22054 is a newly disclosed vulnerability affecting Oracle MySQL Server versions 8.0.33 and prior. This issue, located in the Optimizer component, is classified as easily exploitable. A high privileged attacker with network access can take advantage of this vulnerability, leading to a denial-of-service (DoS) condition. Specifically, they can cause a hang or frequent crashes of the MySQL Server. According to the CVSS 3.1 Base Score, this vulnerability has an impact on availability, with a base score of 4.9. This exploit can be executed via multiple protocols, making it a significant threat to affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MySQL
  • Oracle MySQL Server
  • Fedora Operating System
  • NetApp SnapCenter

Affected Vendors

  • BonqDAO
  • Fedora Project
  • NetApp